The reality for corporate America is not whether organizations and their employees will use artificial intelligence, but how. As reliance on AI grows, organizations should review their acceptable use policies (or “AUPs”), as many do not address or consider AI-related risks.
An effective AUP sets forth the rules upon which employees, contractors, or any other authorized users may utilize artificial intelligence, generative artificial intelligence, machine learning, large language models, or similar technologies (collectively, “AI”) in connection with an organization’s business. An AUP addressing AI is increasingly necessary because tools that are or otherwise utilize AI create legal, business, and security risks that traditional confidentiality, data privacy, and security policies do not address.
For AI, updating AUPs to address AI is less about restriction and more about clarity. Your employees are already using AI to draft emails, summarize documents, and streamline tasks. Although these uses may seem harmless, they can create legal, business, and security problems.
The most critical issue to address is confidentiality and data protection. Not all AI tools handle data the same way. Some store or learn from user inputs in a global model. Others—typically referred to as enterprise or closed models—use inputs solely for the benefit of the organization licensing the model. If employees input nonpublic information into publicly available AI tools, that information can become exposed and may be used to train AI models available to others. To address this risk, your AUP should clearly identify the AI tools employees may use and how.
Another critical issue is output. AI technology is still in its infancy, and AI tools can and will provide false, misleading, incorrect, and sometimes entirely fabricated information. These “hallucinations” require that employees vet the output AI tools provide for accuracy. Federal and state regulators are also increasingly scrutinizing the use of AI for certain legally significant decisions such as hiring, extending credit, and lending decisions so as to require organizations to explain the basis for an outcome that implicitly or explicitly requires human intervention. AUPs can require such “human-in-the-loop” procedures to ensure that people are actively reviewing and approving the AI-generated output used.
Organizations should also establish governance and approval processes for AI tools. Not every AI tool is appropriate for every business function. Certain uses may create heightened legal, operational, or reputational risks. AUPs should identify who is responsible for evaluating and approving AI tools, establish procedures for monitoring their use, and require periodic review of AI-related risks. A defined governance framework helps ensure that AI adoption aligns with the organization’s legal obligations, risk tolerance, and strategic objectives. Training is equally important, as employees require practical instruction on the appropriate use of AI in their day-to-day responsibilities – guidance that written policies alone often cannot adequately convey.
As AI continues to become part of standard business processes, organizations that proactively update their acceptable use policies will be better positioned to manage risk while capturing the benefits of these tools. The objective is not to limit innovation, but to ensure that AI is used in a manner that is consistent with the organization’s obligations, protects sensitive information, and supports business objectives.


